Google addresses 107 Android vulnerabilities, including two zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-48572 +1 in the same advisory: …48633 | Local Privilege Escalation in Android Framework Under Active Exploitation CVE-2025-48572 is a permissions bypass in multiple locations of the Android Framework that allows activities to be launched from the background in violation of normal permission rules. It is triggered locally — per the CVSS vector, an attacker (typically a malicious or compromised app already on the device) needs only low local privileges, with no user interaction required. Successful exploitation yields local escalation of privilege with high impact on confidentiality, integrity, and availability, giving the attacker elevated control over the device. Android devices running an affected version of the Android Framework are in scope; specific affected version numbers are not given in the source data, and the fix shipped in Google's December 2025 Android security update alongside the related in-the-wild flaw CVE-2025-48633. The bug is being exploited in targeted attacks in the wild — Google described it as 'under targeted exploitation' and CISA added it to the KEV catalog on 2025-12-02 (ransomware use: unknown) — although no public proof-of-concept is known and EPSS remains low at 0.3%. Do: Apply Google's December 2025 Android security bulletin patches as soon as the OTA update reaches your devices (Pixel and Google-supported models typically receive monthly updates first) and verify the patch level in system update settings. Because exploitation requires an existing local foothold, review and remove untrusted or sideloaded apps on high-value and managed devices. Under CISA KEV / BOD 22-01 requirements, federal agencies must apply the vendor mitigation or discontinue use of affected products within the required timeframe. | 7.8 group max | <1% | KEV |
| massbillions of Android devices (Android runs on 3+ billion active devices, and the Framework component is present on every Android device) | |
| CVE-2025-48631 | In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. NVD description · AI analysis pending | 6.5 | <1% |
| — |
Full article601 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The company’s latest security update contains the second-highest number of defects patched so far this year.
Listen to this article
0:00
Learn more.
Google disclosed two actively exploited zero-day vulnerabilities Monday, which it addressed among a total of 107 defects in the company’s monthly security update for Android devices.
The zero-days — CVE-2025-48633 and CVE-2025-48572 — are both high-severity defects affecting the Android framework, which attackers can exploit to access information and escalate privileges, respectively. Google said both vulnerabilities, which had not been added to the Cybersecurity and Infrastructure Security Agency’s known exploited vulnerabilities catalog as of Monday afternoon, may be under limited, targeted exploitation.
Google’s public vulnerability disclosure and reporting program for Android has been uneven this year. While the company typically issues dozens of security patches each month, Google reported no vulnerabilities in July and October, just six in August and two vulnerabilities in November.
Google did not respond to questions about the occasional lulls in vulnerability disclosure and hasn’t described any changes to its process that might explain the lower numbers in some months this year.
The company’s latest security update contains the second-highest number of vulnerabilities patched so far this year, followed by the 120 defects it addressed in September.
Google said the most severe vulnerability this month — CVE-2025-48631 — is a critical defect affecting the framework, which attackers can exploit to achieve remote denial of service with no additional execution privileges required.
The Android security bulletin for December includes two patch levels — 2025-12-01 and 2025-12-05 — allowing Android partners to address common vulnerabilities on different devices. Android device manufacturers release security patches on their own schedule after they’ve customized operating system updates for their specific hardware.
The primary security update contains 37 vulnerabilities affecting the framework, including CVE-2025-48631, and 14 defects affecting the system.
The second patch addresses nine vulnerabilities affecting the kernel, including four that are designated critical. The update also contains fixes for two Arm components defects, four Imagination Technologies bugs, 17 vulnerabilities affecting MediaTek components, 13 Unisoc components flaws, and 11 Qualcomm components, including two rated critical.
Google said source code for all vulnerabilities addressed in this month’s Android security bulletin will be released to the Android Open Source Project repository by Wednesday.
Latest Podcasts
Government
FTC rescinds policy requiring health apps to notify customers after a breach
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/android-security-update-december-2025/